Exam 14: IT Security Management and Risk Assessment
Exam 1: Computer Systems Overview45 Questions
Exam 2: Cryptographic Tools45 Questions
Exam 3: User Authentication45 Questions
Exam 4: Access Control45 Questions
Exam 5: Database and Cloud Security45 Questions
Exam 6: Malicious Software45 Questions
Exam 7: Denial-Of-Service Attacks45 Questions
Exam 8: Intrusion Detection45 Questions
Exam 9: Firewalls and Intrusion Prevention Systems45 Questions
Exam 10: Buffer Overflow45 Questions
Exam 11: Software Security45 Questions
Exam 12: Operating System Security45 Questions
Exam 13: Cloud and Iot Security45 Questions
Exam 14: IT Security Management and Risk Assessment45 Questions
Exam 15: IT Security Controls, Plans, and Procedures45 Questions
Exam 16: Physical and Infrastructure Security45 Questions
Exam 17: Human Resources Security45 Questions
Exam 18: Security Auditing45 Questions
Exam 19: Legal and Ethical Aspects45 Questions
Exam 20: Symmetric Encryption and Message Confidentiality45 Questions
Exam 21: Public-Key Cryptography and Message Authentication45 Questions
Exam 22: Internet Security Protocols and Standards45 Questions
Exam 23: Internet Authentication Applications45 Questions
Exam 24: Wireless Network Security45 Questions
Select questions type
_________ is choosing to accept a risk level greater than normal for business reasons.
(Multiple Choice)
4.9/5
(36)
A(n) _________ is a weakness in an asset or group of assets that can be exploited by one or more threats.
(Short Answer)
4.7/5
(36)
The term ________ refers to a document that details not only the overall security objectives and strategies, but also procedural policies that define acceptable behavior, expected practices, and responsibilities.
(Short Answer)
4.9/5
(46)
The __________ approach to risk assessment aims to implement a basic general level of security controls on systems using baseline documents, codes of practice, and industry best practice.
(Short Answer)
4.9/5
(36)
The _________ approach combines elements of the baseline, informal, and detailed risk analysis approaches.
(Short Answer)
4.8/5
(39)
Because the responsibility for IT security is shared across theorganization, there is a risk of inconsistent implementation of security and a loss of central monitoring and control.
(True/False)
4.9/5
(40)
A(n) _________ is anything that has value to the organization.
(Short Answer)
4.9/5
(40)
__________ ensures that critical assets are sufficiently protected in a cost-effective manner.
(Multiple Choice)
4.8/5
(40)
_________ is a process used to achieve and maintain appropriate levels of confidentiality, integrity, availability, accountability, authenticity, and reliability.
(Short Answer)
4.7/5
(33)
Establishing security policy, objectives, processes and procedures is part of the ______ step.
(Multiple Choice)
4.9/5
(37)
The assignment of responsibilities relating to the management of ITsecurity and the organizational infrastructure is not addressed in acorporate security policy.
(True/False)
4.9/5
(33)
A threat may be either natural or human made and may be accidentalor deliberate.
(True/False)
4.9/5
(34)
A ________ is anything that might hinder or present an asset from providing appropriate levels of the key security services.
(Multiple Choice)
4.8/5
(45)
ISO details a model process for managing information security that comprises the following steps: plan, do, ________, and act.
(Short Answer)
4.9/5
(35)
The four approaches to identifying and mitigating risks to an organization's IT infrastructure are: baseline approach, detailed risk analysis, combined approach, and __________ approach.
(Short Answer)
4.9/5
(38)
Implementing the risk treatment plan is part of the ______ step.
(Multiple Choice)
5.0/5
(35)
Not proceeding with the activity or system that creates the risk is _________.
(Short Answer)
4.8/5
(43)
The _________ approach involves conducting a risk analysis for the organization's IT systems that exploits the knowledge and expertise of the individuals performing the analysis.
(Multiple Choice)
4.9/5
(30)
_________ include management, operational, and technical processes and procedures that act to reduce the exposure of the organization to some risks by reducing the ability of a threat source to exploit some vulnerabilities.
(Multiple Choice)
4.8/5
(34)
Legal and regulatory constraints may require specific approaches torisk assessment.
(True/False)
4.9/5
(31)
Showing 21 - 40 of 45
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)